Dr. Stjepan Picek
Professor, University of Zagreb, Croatia
Associate Professor of Digital Security, Radboud University, Netherlands
https://www.ru.nl/en/people/picek-s
Professor, University of Zagreb, Croatia
Associate Professor of Digital Security, Radboud University, Netherlands
https://www.ru.nl/en/people/picek-s
CTO of IBM Quantum Safe, IBM Research Europe, Zurich, Switzerland
https://research.ibm.com/people/michael-osborne
Director of Malaysian Cryptology Technology and Management Centre, Malaysia
Artificial intelligence is rapidly changing how we analyze, attack, and protect cryptographic systems. After initially being treated with considerable skepticism, AI-based techniques now achieve state-of-the-art results across several areas of cryptographic and hardware security. Neural networks have transformed profiled side-channel analysis, improved the modeling and evaluation of physically unclonable functions, supported the detection of hardware Trojans and implementation weaknesses, and assisted increasingly sophisticated forms of cryptanalysis. At the same time, the growing use of AI introduces new security challenges. AI models are often difficult to interpret, reproduce, and validate, while their behavior can be manipulated through adversarial examples, poisoned training data, backdoors, model extraction, and other attacks. These concerns become even more important as large language models and autonomous AI systems are deployed in security-critical environments.
This talk explores the bidirectional relationship between AI and cryptography. First, we will examine examples in which machine learning has improved cryptanalysis and hardware-security evaluation, as well as the methodological limitations that can make such results unreliable or misleading. We will then reverse the perspective and investigate how cryptographic concepts and techniques can contribute to protecting AI systems. Topics will include cryptanalysis-inspired model extraction, cryptographically indistinguishable backdoors, secure distributed learning, and mechanisms for verifying computations and model behavior.
The talk will conclude by outlining open challenges at the intersection of these fields. Rather than viewing AI and cryptography as separate disciplines, the talk argues that their interaction is becoming a central part of the future security landscape.
Dr. Stjepan Picek